Описание
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext. This issue has been patched via commit 4e075d3.
Ссылки
- Product
- Product
- Patch
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.0 (включая)
cpe:2.3:a:star-citizen:embedvideo:*:*:*:*:*:mediawiki:*:*
EPSS
Процентиль: 19%
0.00062
Низкий
8.6 High
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 8.6
github
5 месяцев назад
Star Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes
EPSS
Процентиль: 19%
0.00062
Низкий
8.6 High
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79